Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,12 @@ class CredentialRedactor:
callers. The class operates on plain strings as well as nested dictionaries,
lists, and tuples, replacing detected secret values with a stable
placeholder.

.. note::
Redaction covers secret-like material only (the ``PATTERNS`` set).
PII/CRI (email, phone, SSN, credit card, IP address) is detected by
:meth:`find_pii_matches` / :meth:`contains_pii` but is not removed by
:meth:`redact`.
"""

# Python's stdlib ``re`` does not support per-pattern timeouts. These
Expand Down Expand Up @@ -249,6 +255,10 @@ def redact(cls, value: str | None) -> str:
pattern consume the anchor keyword of a later one, which would remove
less than detection reported and leave a secret in place.

This method is secrets-only: it redacts the ``PATTERNS`` set, not
``PII_PATTERNS``. Use :meth:`find_pii_matches` / :meth:`contains_pii`
when PII (email, phone, SSN, credit card, IP address) must be detected.

Args:
value: String content that may contain credential-like material.

Expand Down Expand Up @@ -341,6 +351,9 @@ def redact_dictionary(cls, mapping: dict[str, Any] | None) -> dict[str, Any]:
def redact_data_structure(cls, value: Any) -> Any:
"""Recursively redact nested strings in dicts, lists, and tuples.

Like :meth:`redact`, this covers secret-like patterns only; PII is
detected but not removed.

Args:
value: Any Python value that may contain nested strings.

Expand Down
Loading